CVE-2024-26251HighCVSS 6.8

Microsoft SharePoint Server Spoofing Vulnerability

Published
April 9, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires multiple conditions to be met, such as specific application behavior, user actions, manipulation of parameters passed to a function, and impersonation of an integrity level token.

🎯 Affected products3

  • Microsoft SharePoint Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002580 (Security Update) — fixed build 16.0.10409.20027 KB5002581 (Security Update) — fixed build 16.0.17328.20246 KB5002583 (Security Update) — fixed build 16.0.5443.1000

🔗 References (7)